The Accidental Discovery of a New Vulnerability in Google's OAuth Implementation

  Рет қаралды 36,181

Black Hat

Black Hat

2 ай бұрын

Beware, dear friends, the cautionary tale of the cloud provider that broke its own security model. Ignoring RFCs! Putting plaintext passwords in scripts - and printing them in books! It's a crazy story, but one that may nonetheless resonate with enterprise security practitioners everywhere.
In early 2021, I identified a client impersonation vulnerability in a series of Google "first-party" applications. This vulnerability allows an attacker to present themselves both to a user and to Google as one of these applications, and enjoy all the privileges therein....
By: Brian Smith-Sweeney
Full Abstract and Presentation Materials: www.blackhat.com/us-23/briefi...

Пікірлер
НЕОБЫЧНЫЙ ЛЕДЕНЕЦ
00:49
Sveta Sollar
Рет қаралды 6 МЛН
Buy Feastables, Win Unlimited Money
00:51
MrBeast 2
Рет қаралды 80 МЛН
Uma Ki Super Power To Dekho 😂
00:15
Uma Bai
Рет қаралды 34 МЛН
Zero Trust Explained | Real World Example
21:46
CertBros
Рет қаралды 12 М.
GPT-4o - Full Breakdown + Bonus Details
18:43
AI Explained
Рет қаралды 138 М.
Something Rotten in the State of Data Centers
40:27
Black Hat
Рет қаралды 8 М.
Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)
17:34
So You Think You Know Git - FOSDEM 2024
47:00
GitButler
Рет қаралды 911 М.
Keynote: My Lessons from the Uber Case
1:05:00
Black Hat
Рет қаралды 2,3 М.
researchers find unfixable bug in apple computers
8:32
Low Level Learning
Рет қаралды 677 М.
Why is JWT popular?
5:14
ByteByteGo
Рет қаралды 250 М.